{"id":"CVE-2023-25758","details":"Onekey Touch devices through 4.0.0 and Onekey Mini devices through 2.10.0 allow man-in-the-middle attackers to obtain the seed phase. The man-in-the-middle access can only be obtained after disassembling a device (i.e., here, \"man-in-the-middle\" does not refer to the attacker's position on an IP network). NOTE: the vendor states that \"our hardware team has updated the security patch without anyone being affected.\"","modified":"2026-07-15T01:49:17.122900314Z","published":"2023-02-14T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/25xxx/CVE-2023-25758.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://fortune.com/crypto/2023/02/09/cyber-firm-cracks-onekey-crypto-wallets-in-video-raises-questions-hardware-security/amp/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/25xxx/CVE-2023-25758.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-25758"},{"type":"PACKAGE","url":"https://github.com/OneKeyHQ/firmware"},{"type":"ARTICLE","url":"https://blog.onekey.so/our-response-to-recent-security-fix-reports-13914fea8afd"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/onekeyhq/firmware","events":[{"introduced":"0"},{"fixed":"e901cefe537215cc644b6c570c7075ae90ff050c"},{"fixed":"2d2503dfa0b847301e99ef0644acbbf9cf9099a8"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"4.0.0"},{"fixed":"2.10.0"}],"source":"DESCRIPTION"}}],"versions":["touch/v3.4.0","mini/v2.8.0","mini/v2.7.0","mini/v2.6.0","mini/v2.5.0","mini/v2.4.0","mini/v2.3.0","onekey/v2.0.4","onekey/v2.0.3","bixin/v1.9.8","bixin/v1.9.7","python/v0.12.2","python/v0.12.1","bixin/v1.9.6","bixin/v1.9.5","bixin/v1.9.4.1","bixin/v1.9.4","python/v0.12.0","python/v0.11.5","python/v0.11.4","python/v0.11.3","core/v2.0.10","core/br2.0.1","core/bl2.0.2","core/v2.0.9","core/v2.0.8","core/v2.0.7","core/v2.0.6","core/v2.0.5","core/bl2.0.1","core/br2.0.0","core/bl2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-25758.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}